Sandworm-Linked UAC-0145 Exploits Fake Interviews to Deploy Malware

TL;DR. A Russian state-backed hacking group uses fake job interviews to deploy a custom VPN tool capable of executing commands on compromised systems. - UAC-0145, associated with Sandworm, targets organizations with sophisticated social engineering tactics. - The custom SuperOps RMM agent and remote access VPN bypass security and enable command execution. - Threat actors leverage these tools to maintain persistence and conduct further malicious activities within networks.

Sources

Back to QLANKR News